this post was submitted on 28 Aug 2023
1461 points (97.7% liked)

Lemmy.World Announcements

28631 readers
40 users here now

This Community is intended for posts about the Lemmy.world server by the admins.

For support with issues at Lemmy.world, go to the Lemmy.world Support community.

Support e-mail

Any support requests are best sent to [email protected] e-mail.

Donations 💗

If you would like to make a donation to support the cost of running this platform, please do so at the following donation URLs.

If you can, please use / switch to Ko-Fi, it has the lowest fees for us

Ko-Fi (Donate)

Bunq (Donate)

Open Collective backers and sponsors

Patreon

founded 1 year ago
MODERATORS
1461
submitted 10 months ago* (last edited 9 months ago) by lwadmin to c/lemmyworld
 

Lemmy.world is temporarily disabling open signups and moving to an application-required signup process, due to ongoing issues with malicious bot accounts.

We know this is a major step to take, but we believe that it’s the right one for both us and our community right now.

We’re working on a better long-term technical solution to these bots, but that will take time to create, test, and verify that it doesn’t cause any problems with federation and how our users use our site, and we’d rather make sure we get it right than have a site that’s broken.

We’re making this change on 28 Aug 2023, and don’t have a specific timeline for how long registrations will require an application, but we will post an update once our new anti-abuse measures are in place and working.

Take care, LW Team

top 50 comments
sorted by: hot top controversial new old
[–] devious 267 points 10 months ago (2 children)

You gotta do, what you gotta do!

Thanks as always for the hard work and transparency.

[–] lwadmin 118 points 10 months ago (1 children)

Thank you for the kindness!

[–] GONADS125 32 points 10 months ago* (last edited 10 months ago) (1 children)

I hope you guys are doing okay having to see all that shit.. No shame in reaching out to mental health professionals. Makes me sad imagining you guys picking up emotional baggage and trauma having to see all that to protect the community.

I appreciate you guys looking out for us, but I hope you all have proper support yourselves.

load more comments (1 replies)
load more comments (1 replies)
[–] FlyingSquid 179 points 10 months ago (6 children)

Whew, I'm glad I got in before this or my fellow homo sapiens might not have noticed I was also a fellow homo sapiens like them and definitely not a robot.

[–] hemmes 41 points 10 months ago (1 children)

You’re clearly a Mollusc

[–] FlyingSquid 34 points 10 months ago

How dare you! I am no mere mollusc, I am a proud Todarodes pacificus and definitely not a robot squid.

[–] Dienes 27 points 10 months ago (1 children)

OK BUT WHY ARE YOU SCREAMING

[–] FlyingSquid 31 points 10 months ago (4 children)

I had a nightmare about electric sheep. Don't we all?

load more comments (4 replies)
load more comments (4 replies)
[–] kadu 146 points 10 months ago* (last edited 10 months ago) (3 children)

No place is safe from this, unfortunately. I moderated 2 big brazilian subreddits, and then decided to volunteer to help a smaller one. I had a day (and to be honest, an entire week) absolutely ruined when somebody did indeed set a bot to post large amounts of CSAM to the subreddit. Luckily I was online to quickly purge it all, and Reddit's admins did remove the accounts pretty much instantly, but I feel for every Lemmy admin that even caught a glimpse of this material and now have to purge their computers and honestly, their minds, from that. Sorry to hear it happened.

[–] Kethal 42 points 10 months ago (1 children)

Two brazilian sounds like a lot.

load more comments (1 replies)
[–] snausagesinablanket 22 points 10 months ago* (last edited 10 months ago) (3 children)

CSAM

I just looked up this acronym and am sorry I did.

load more comments (3 replies)
load more comments (1 replies)
[–] input 130 points 10 months ago (1 children)

Hope it restricts the attack surface, why do people have to be such knobs

[–] pretzelz 118 points 10 months ago* (last edited 10 months ago) (11 children)

Not wanting to be too conspiratorial, but it isn't necessarily people simply doing this out of the badness of their hearts. The fediverse is a disruptive platform and there are many parties with deep pockets that might happily funnel a little bit of cash to certain consultancies in certain countries to stop things and add friction to this platform before it really takes off. Nothing like a little bit of corporate sabotage!

[–] Pregnenolone 59 points 10 months ago (15 children)

That sounds exactly like the badness in people’s hearts though.

load more comments (15 replies)
[–] Aux 41 points 10 months ago (1 children)

This is a very silly conspiracy theory. Big corps don't give a shit about Lemmy, but there are plenty of script kiddies who want to hack easy targets. Contrary to your belief, there are plenty of dumb idiots with plenty of badness in their hearts.

[–] [email protected] 19 points 10 months ago* (last edited 10 months ago) (17 children)

Big corps are more sociopathic than you realise. There are so many underhanded games going on at that level it will make your head spin.

Big businesses indirectly and sometimes directly fund APT groups. They will buy things that give them anonymous access to competitor trade secrets, or fund attack campaigns against competitors. This sounds like the kind of attack campaign a competitor might launch as part of a one-two combo. This is the first part, the second part is to get editorials out there regarding how lemmy.world is full of CSAM.

load more comments (17 replies)
[–] givesomefucks 35 points 10 months ago

The alt right instance has been fucking with world since they were defederated...

This is something right up their alley, so the simplest solution is they're doing it.

[–] [email protected] 25 points 10 months ago (4 children)

Come on people, Lemmy's user base is what, a few hundred thousand? A million tops? Which "parties with deep pockets" is this disrupting? The Lemmy userbase is a rounding error on the number of users of other popular social medias.

"Don't want to be too conspiratorial, but let me continue to drop a ridiculous conspiracy with no evidence"

load more comments (4 replies)
load more comments (7 replies)
[–] Astrealix 81 points 10 months ago

Looks like even this place couldn't keep it up. Unfortunate. Thanks admins for the transparency though.

[–] DelvianSeek 70 points 10 months ago

Good call. Thank you for doing what you need to do to support the site and protect the users as necessary. And as always, the honesty and transparency is appreciated.

[–] ObviouslyNotBanana 63 points 10 months ago

I think it's the right call honestly. We've grown so quick that it must be hard to manage by now.

[–] 007v2 53 points 10 months ago

Thanks for all the work you do! It isn’t unappreciated.

[–] GlitzyArmrest 51 points 10 months ago

Hope it helps with the recent abuse.

[–] [email protected] 48 points 10 months ago* (last edited 10 months ago)

https://github.com/bumble-tech/private-detector

Do you guys think this could help? I remembered reading bumble open sourced their image detection system.

[–] scarabic 42 points 10 months ago

If you could give me the numbers of new accounts monthly I would look into CloudFlare. If I can afford it I will even pay for it.

[–] pm_boobs_send_nudes 37 points 10 months ago (1 children)

I don't blame you for taking that decision. But it's sad that this will deter legitimate users away, some of whom would've signed up otherwise.

[–] ConstipatedWatson 33 points 10 months ago* (last edited 9 months ago) (1 children)

I guess I'm out of the loop, perhaps because I mostly browse communities I subscribed to, but...

What happened? Lots of spammy bots signing up and spamming the site? I guess I didn't notice where I was looking

Also, what does application based sign up mean?

Anyhow, Lemmy.World and Lemmy (in general) are growing nicely, so what's needed to defend them is cool.

Edit: fixed grammar

[–] [email protected] 61 points 10 months ago* (last edited 10 months ago) (1 children)

Troll / spam accounts posted CSAM in [email protected]. That spread with federation and every admin ended up involuntarily hosting such content.

Application based sign up means that if a user wants to subscribe they have to fill out a form and a .world admin gets to review it and approve or reject their sign up. It's a measure of controlling who gets in and limiting the amount of bots and possibly troll that join an instance.

[–] [email protected] 28 points 10 months ago

To make it clear, the form is virtually the same as before with one additional question. It just asks you to state you read the note that is the same as the note in the post above. The application is virtually identical beyond that. But, the biggest difference, is like you said, an admin needs to approve it.

[–] The_Picard_Maneuver 30 points 10 months ago* (last edited 10 months ago) (8 children)

Is image posting temporarily turned off for lemmy.world users too?

Since last night, I've been unable to post (tested in [email protected], [email protected], and [email protected]). Switched to an alt account on a different instance and had no issue.

(getting JSON error: unexpected character at line 1 column 1)

load more comments (8 replies)
[–] TropicalDingdong 26 points 10 months ago (1 children)
load more comments (1 replies)
[–] Candelestine 23 points 10 months ago

Glad to hear. Obviously this is less than ideal, but working towards solutions is what's important.

[–] teruma 20 points 10 months ago (1 children)

Will this make it easier to reopen federation with instances that were concerned about abuse of our open sign up policy? (or was the issue with beehaw resolved while I wasn't looking?)

[–] [email protected] 22 points 10 months ago

If it's temporary, likely not. The concern from most of the instances is that open subs mean literally anyone and anything can join, including bots which create account after account, just moving on when the original is banned. "We are closing open signups for now" is non committal, I'm betting the only way things get refederated is if World commits to this change for the long term.

load more comments
view more: next ›